Forum search & shortcuts

CRC security issues...
 

[Closed] CRC security issues?

Posts: 3775
Free Member
Topic starter
 
[#2533694]

http://www.bikeradar.com/forum/viewtopic.php?p=16801436#16801436
Heads up -
Possible chain reaction security breach?


 
Posted : 05/03/2011 11:01 pm
Posts: 0
Free Member
 

This happened to me, 4 attempts by t mobile to take 2 quid. Basically checking the card to see if they can bleed it dry. My bank alerted me straight away and cancelled my card.


 
Posted : 05/03/2011 11:17 pm
Posts: 0
Free Member
 

This has cropped up on here every six months or so. After a spate of fraud I used to be V susiciously of CRC / Wiggle but it turned out to be a local BAA parking machine had a skimmer installed.

This was from the days I used to work in the CC IT world (a few years back). I seriously doubt CRC / Merlin / Wiggle etc (there were rumours about all of these) are allowed to store any CC info in the clear. All transactions are transferred to big name players : Worldpay etc.

Ultimatley, pay by Credit Card - you've got very little to worry about.

Your local petrol station is FAR FAR more likely to be skimming your details than a bike shop.


 
Posted : 05/03/2011 11:26 pm
Posts: 0
Free Member
 

couldashouldawoulda - the likes of CRC etc are able to take partial and/or delayed payment. That being the case, they must be holding on to the card details somewhere and only presenting them to WorldPay (or equivalent) when the goods are ready to be dispatched?


 
Posted : 05/03/2011 11:42 pm
Posts: 3775
Free Member
Topic starter
 

Couldasoulda
I've had card fraud tracked back to both amazon and a shell petrol station in the past
Both times it was known to mbna, I wasn't the first
No idea in this case if there is genuine Crc link but thought I'd best just warn people in case I know alot of people got a voucher and used Crc last wrk so could be concerned


 
Posted : 05/03/2011 11:46 pm
Posts: 0
Free Member
 

I only pay using Pay Pal on CRC .in the hope that it is safer than putting my card details in..


 
Posted : 06/03/2011 12:07 am
Posts: 0
Free Member
 

Just checked my online banking and had £30 O2 prepay taken out yesterday. I also took advantage of the £10 voucher from CRC...

Looks like i'll be calling the bank 1st thing 🙁


 
Posted : 06/03/2011 12:09 am
Posts: 0
Free Member
 

are you safe using paypal?
guess so as they dont send over your details?
always makes me cringe when i checkout on the 'mobile' site


 
Posted : 06/03/2011 12:41 am
Posts: 0
Free Member
 

This could well be true. Had 4 unrecognised transactions go out in one day this week after a CRC order, 2x £10
O2 top-up cards then stung for over £600. A call to banks fraud department, card cancelled and money refunded in 24 hours


 
Posted : 06/03/2011 5:10 am
 anc
Posts: 0
Free Member
 

Hmmm this is interesting.. I had 2 fraudulent transactions on the credit card this week. The transaction before these... Yep you've guessed it... Chainreaction!! 😡


 
Posted : 06/03/2011 7:43 am
Posts: 0
Free Member
 

I ordered from Chainreaction last week and guess what???
I've not had any fraud on my account


 
Posted : 06/03/2011 8:12 am
Posts: 0
Free Member
 

Druidh. Re: delayed payments, if you do these properly then you still don' t need to hold the credit card details, world pay or whoever still handle it all, I'm building a site at the moment that does exactly this. Not saying that crc do, do this but they don't have to.


 
Posted : 06/03/2011 8:29 am
 beej
Posts: 4221
Full Member
 

I too ordered from CRC using the voucher - and no fraud on my account. I did use paypal though.

If your vouchers worked then they were probably genuine as they were verified by the CRC site.

Nothing in this thread constitutes proof either way.


 
Posted : 06/03/2011 9:04 am
 Drac
Posts: 50638
 

Just checked as used CRC a fair bit laterly. There's loads of indiscriminate payments been taken off my card, few £ here looks mostly on pointless rubbish. All of them me.


 
Posted : 06/03/2011 10:28 am
Posts: 0
Free Member
 

mahowlett - care to explain how that works?


 
Posted : 06/03/2011 10:43 am
Posts: 0
Free Member
 

I was called by HSBC fraud detection dept on Friday. £210 taken fraudulently, they then attempted a similar amount again which was then declined. I’d used the card for the first time at CRC a few days before.

Beej: nothing to do with dodgy vouchers.

Not proof in anyway, but I will be mentioning CRC when I speak to the fraud dept tomorrow.


 
Posted : 06/03/2011 11:02 am
Posts: 0
Free Member
 

I took advantage of the CRC £10 voucher on monday, thursday two lots of £15 were taken out of my account for O2 prepay.

Could be coincidence but I was thinking it would be something online rather than having my card swiped. I'm by no means the only person being relieved of their money for [url= http://www.google.co.uk/search?sourceid=chrome&ie=UTF-8&q=O2+prepay+slough ]O2 prepay in slough.[/url]

Debit card now blocked, money being refunded and new card being sent out.


 
Posted : 06/03/2011 11:49 am
Posts: 0
Free Member
 

Druidh, they're called deferred payments, and I think most of the major gateways support them now basically you send all the details to the gateway in the normal way and the transaction is authorised as usual but the gateway doesn't actually put the payment until you send them notification that it should be paid. This has to be sent in a relatively short timescale though to stop you taking payments months after authorising them, I think the limit is in the order of a few weeks.


 
Posted : 06/03/2011 12:01 pm
Posts: 0
Free Member
 

Who holds the gateway?

The reason I'm asking is that we do a simple re-direct to WorldPay when the order is placed - and the customer has to just pay up-front. We never hold any card details (it's illegal to do so in Scotland), whereas many of these other sites do hold them - to save the customer having to re-enter them each time.


 
Posted : 06/03/2011 12:04 pm
Posts: 621
Free Member
 

Hmmm, also had my card done a day after putting through a CRC order- £30 of o2 top-ups.


 
Posted : 06/03/2011 12:21 pm
Posts: 2874
Free Member
 

Not a new thing - I had O2 top ups on my card after using CRC over a year ago, despite never having an O2 phone.


 
Posted : 06/03/2011 12:31 pm
Posts: 0
Free Member
 

i used to work at RBS, internet companys do this all the time, they pay their staff min wage and then wonder why shit like this happens!


 
Posted : 06/03/2011 12:51 pm
Posts: 0
Free Member
 

Druidh, worldpay is the payment gateway, you'll need to go to their support site to see how it's done on their system, it's illegal for a site to hold cc details unless they are PCI complaint, something which is quite hard to get and potentially means you could be liable for loads of cash if a card is used fraudulently,


 
Posted : 06/03/2011 1:05 pm
Posts: 0
Free Member
 

Me too, Used the CRC voucher Monday, has 2 O2 Prepay debits of £15 in Wednesday. Gits!


 
Posted : 06/03/2011 1:21 pm
Posts: 814
Free Member
 

i have had exactly the same, twice, in the past. had never made a CRC link, but they both made o2 prepay things. i guess crc may have a hole? off to check my accounts


 
Posted : 06/03/2011 3:01 pm
Posts: 0
Free Member
 

Another order to CRC last week and like everyone else here had £30 of O2 top ups taken from my account and an attempt to send some form of online fax! Props to the bank for acting quickly, stopping the card and refunding the money. Also used the voucher and thought payment would be fairly secure using paypal!


 
Posted : 06/03/2011 3:30 pm
 ART
Posts: 1073
Full Member
 

MMm just read this and have checked my account. All fine at the moment having used the voucher last week, so am guessing prob OK. Thanks for the heads up though.


 
Posted : 06/03/2011 4:23 pm
Posts: 0
Free Member
 

If hundreds or even thousands of card details were harvested, I doubt that they'd test absolutly everyone they'd gathered.

This is only the 2nd time that an internet retailer has been the prime suspect for any fraud on my account, usually it's petrol stations.

I can't say for definite that my details got into the wrong hands via CRC, but there does appear to be a pattern emerging.

Bank have canceled my card and the fraud team have been prompted to call me tomorrow. 🙂


 
Posted : 06/03/2011 4:59 pm
Posts: 0
Free Member
 

my debit card was cancelled last week by my bank, no fraudulent transactions, but it was 3-4 days after I placed an order at CRC as well...


 
Posted : 06/03/2011 5:04 pm
 meka
Posts: 0
Free Member
 

Had a call from my CC on Fri. Suspect transaction, someone tried to buy something from Apple.

As I now live abroad and the locals don't like CC, I only use this card online. I keep this card for bike stuff, so for the last year or so it has only been used for Wiggle and CRC.

Card canceled and new one on its way.


 
Posted : 06/03/2011 8:58 pm
Posts: 0
Full Member
 

I hate to say this but I win.
Spent the voucher and more on Sunday,payed with Debit card, and on Thursday. . . £1,305.95 gone out of my account to John lewis.
And no, it wasn't me! :oops:Now in the process of getting my funds back off TSB.


 
Posted : 06/03/2011 9:12 pm
 d4
Posts: 0
Free Member
 

Yup me too, order to CRC Monday night. Call from bank Saturday saying some one had attempted to buy O2 prepays. FWIW didn't use a voucher.


 
Posted : 06/03/2011 9:19 pm
Posts: 14942
Full Member
 

And are CRC looking into this in any way? Any official comment from them?


 
Posted : 06/03/2011 9:31 pm
Posts: 0
Free Member
 

Stocked up on brake pads last week using the voucher. Paid on a seldom used credit card. Call on Thursday from cc security re 2 x £20 Vodaphone top-ups, 2nd of which they refused. Card cancelled.
Having read the above all seems very suspicious: as per BoardinBob would anyone at CRC care to comment?


 
Posted : 06/03/2011 9:50 pm
 mc2
Posts: 0
Free Member
 

Me Too!

Just checked my account and £15 O2 top up debited. Called and cancelled card etc etc!!

Would be interested to hear what CRC have to say.......


 
Posted : 06/03/2011 9:57 pm
Posts: 3400
Free Member
 

I have used the voucher recently and no apparent problems but I paid through paypal....is paypal a lot more secure then direct cc???


 
Posted : 06/03/2011 10:28 pm
Posts: 143
Free Member
 

Me too, bought some grips on CRC last week, Saturday morning credit card company phones me to say I have been diddled, 3 times £20 vodaphone top ups, £15 O2 top up and money to a charity in the US? Card cancelled and new one in the post, big thums up to mint for being on the ball!
PJ.


 
Posted : 06/03/2011 11:46 pm
Posts: 34548
Full Member
 

has anyone contacted crc about this?

in the light of them being 'the worlds largest online bicycle retailer' thats potentialy a lot of people scammed
[url= http://www.bikeradar.com/mtb/news/article/chain-reaction-cycles-behind-the-scenes-29496 ]http://www.bikeradar.com/mtb/news/article/chain-reaction-cycles-behind-the-scenes-29496[/url]

thankfully i use paypal as i have ordered from them quite a bit lately


 
Posted : 07/03/2011 12:02 am
Posts: 632
Free Member
 

The snapper from bike radar... Snooping around the offices a few days ago....he's got to be suspect number 1......

http://www.bikeradar.com/gallery/article/chain-reaction-cycles-behind-the-scenes-29496?img=36&pn=chain-reaction-cycles--behind-the-scenes&mlc=news%2Farticle%2Fimage


 
Posted : 07/03/2011 12:35 am
Posts: 0
Free Member
 

Bought a few things off CRC over the past 2 weeks. First time used Paypal, second time used a combination of £10 off voucher, gift vouchers and Paypal. Don't seem to have a dodgy transactions on my bank account.

and money to a charity in the US?

My gf had this a few months back, some family support charity in Texas 😕 Got the $20 back though


 
Posted : 07/03/2011 2:55 am
Posts: 0
Free Member
 

Ooh now then, I ordered some stuff from CRC at the beginning of January which never left the "processing" stage, even when I contacted them a fortnight ago.

They then promptly refunded me the money and apologised, and was then stung for a mysterious £30.00 O2 TopUp Prepay purchase !

I have never been fleeced online before and couldn't understand how my details had been stolen.

Coincidence or a pattern emerging here peeps ?


 
Posted : 07/03/2011 4:17 am
Posts: 7766
Full Member
 

Brilliant! Bought from CRC for the first time in 6 months on Friday, about to test the whole 24hr helpline thing....


 
Posted : 07/03/2011 6:38 am
Posts: 177
Free Member
 

Yep 2 lots of £15 quid taken from my account for O2 top up....only used the card at CRC, in the last 3 weeks.

Not only that but i placed the order on monday and I am still waiting for the stuff to be sent.

I think the UK bike store will become my new online parts provider, always had good service from them, and they answer the phones.


 
Posted : 07/03/2011 9:07 am
Posts: 4
Free Member
 

+1 me too, £500 taken on some dodgy canadian airline ticket

I've emailed them to let them know

cheers!


 
Posted : 07/03/2011 9:56 am
Posts: 0
Free Member
 

CRC might only be licensed to hold CC details in the servers RAM.

i.e. when the server is switched off, there is no trace of the details.


 
Posted : 07/03/2011 10:43 am
Page 1 / 22